The Experts below are selected from a list of 2562 Experts worldwide ranked by ideXlab platform
K. Ray J. Liu - One of the best experts on this subject based on the ideXlab platform.
-
Forensics vs anti Forensics a decision and game theoretic framework
International Conference on Acoustics Speech and Signal Processing, 2012Co-Authors: Matthew C. Stamm, Sabrina W. Lin, K. Ray J. LiuAbstract:In order to combat the spread of digital forgeries, researchers have developed a variety of Forensic techniques to verify the authenticity of digital multimedia files. Though many of these techniques can reliably detect traditional forgeries, recent research has shown that they can easily be fooled by anti-Forensic operations designed to hide evidence of forgery. In response, new Forensic techniques have been developed to detect the use of anti-Forensics. In light of this, there is now a need to develop a theoretical understanding of the interactions between a forger using anti-Forensics and a Forensic Investigator. In this paper, we propose techniques to evaluate the performance of anti-Forensic algorithms along with a game theoretic framework for analyzing the interplay between Forensics and anti-Forensics. Furthermore, we propose a new automatic video frame deletion detection technique along with a technique to detect the use of video anti-Forensics. We evaluate these techniques using our proposed analytical framework.
-
Temporal Forensics and Anti-Forensics for Motion Compensated Video
IEEE Transactions on Information Forensics and Security, 2012Co-Authors: Matthew C. Stamm, Sabrina W. Lin, K. Ray J. LiuAbstract:Due to the ease with which digital information can be altered, many digital Forensic techniques have been developed to authenticate multimedia content. Similarly, a number of anti-Forensic operations have recently been designed to make digital forgeries undetectable by Forensic techniques. However, like the digital manipulations they are designed to hide, many anti-Forensic operations leave behind their own Forensically detectable traces. As a result, a digital forger must balance the trade-off between completely erasing evidence of their forgery and introducing new evidence of anti-Forensic manipulation. Because a Forensic Investigator is typically bound by a constraint on their probability of false alarm (P_fa), they must also balance a trade-off between the accuracy with which they detect forgeries and the accuracy with which they detect the use of anti-Forensics. In this paper, we analyze the interaction between a forger and a Forensic Investigator by examining the problem of authenticating digital videos. Specifically, we study the problem of adding or deleting a sequence of frames from a digital video. We begin by developing a theoretical model of the Forensically detectable fingerprints that frame deletion or addition leaves behind, then use this model to improve upon the video frame deletion or addition detection technique proposed by Wang and Farid. Next, we propose an anti-Forensic technique designed to fool video Forensic techniques and develop a method for detecting the use of anti-Forensics. We introduce a new set of techniques for evaluating the performance of anti-Forensic operations and develop a game theoretic framework for analyzing the interplay between a Forensic Investigator and a forger. We use these new techniques to evaluate the performance of each of our proposed Forensic and anti-Forensic techniques, and identify the optimal actions of both the forger and Forensic Investigator.
Matthew C. Stamm - One of the best experts on this subject based on the ideXlab platform.
-
Forensics vs anti Forensics a decision and game theoretic framework
International Conference on Acoustics Speech and Signal Processing, 2012Co-Authors: Matthew C. Stamm, Sabrina W. Lin, K. Ray J. LiuAbstract:In order to combat the spread of digital forgeries, researchers have developed a variety of Forensic techniques to verify the authenticity of digital multimedia files. Though many of these techniques can reliably detect traditional forgeries, recent research has shown that they can easily be fooled by anti-Forensic operations designed to hide evidence of forgery. In response, new Forensic techniques have been developed to detect the use of anti-Forensics. In light of this, there is now a need to develop a theoretical understanding of the interactions between a forger using anti-Forensics and a Forensic Investigator. In this paper, we propose techniques to evaluate the performance of anti-Forensic algorithms along with a game theoretic framework for analyzing the interplay between Forensics and anti-Forensics. Furthermore, we propose a new automatic video frame deletion detection technique along with a technique to detect the use of video anti-Forensics. We evaluate these techniques using our proposed analytical framework.
-
Temporal Forensics and Anti-Forensics for Motion Compensated Video
IEEE Transactions on Information Forensics and Security, 2012Co-Authors: Matthew C. Stamm, Sabrina W. Lin, K. Ray J. LiuAbstract:Due to the ease with which digital information can be altered, many digital Forensic techniques have been developed to authenticate multimedia content. Similarly, a number of anti-Forensic operations have recently been designed to make digital forgeries undetectable by Forensic techniques. However, like the digital manipulations they are designed to hide, many anti-Forensic operations leave behind their own Forensically detectable traces. As a result, a digital forger must balance the trade-off between completely erasing evidence of their forgery and introducing new evidence of anti-Forensic manipulation. Because a Forensic Investigator is typically bound by a constraint on their probability of false alarm (P_fa), they must also balance a trade-off between the accuracy with which they detect forgeries and the accuracy with which they detect the use of anti-Forensics. In this paper, we analyze the interaction between a forger and a Forensic Investigator by examining the problem of authenticating digital videos. Specifically, we study the problem of adding or deleting a sequence of frames from a digital video. We begin by developing a theoretical model of the Forensically detectable fingerprints that frame deletion or addition leaves behind, then use this model to improve upon the video frame deletion or addition detection technique proposed by Wang and Farid. Next, we propose an anti-Forensic technique designed to fool video Forensic techniques and develop a method for detecting the use of anti-Forensics. We introduce a new set of techniques for evaluating the performance of anti-Forensic operations and develop a game theoretic framework for analyzing the interplay between a Forensic Investigator and a forger. We use these new techniques to evaluate the performance of each of our proposed Forensic and anti-Forensic techniques, and identify the optimal actions of both the forger and Forensic Investigator.
Yin Zhang - One of the best experts on this subject based on the ideXlab platform.
-
AndroKit: A toolkit for Forensics analysis of web browsers on android platform
Future Generation Computer Systems, 2019Co-Authors: Muhammad Asim, Muhammad Faisal Amjad, Waseem Iqbal, Hammad Afzal, Haider Abbas, Yin ZhangAbstract:Abstract Due to the pervasive nature of smart phones and devices, users are becoming more and more dependent on such devices for accessing online information. Pervasive use of smart devices has significantly enlarged the attack surface and resulted in a proportional complication of cyber threat intelligence gathering. For such devices, web browsers have become a primary means for accessing information provided on Internet as well as file systems and therefore, web browser Forensics is an important component of cyber threat intelligence. The basics of web browser Forensics revolve around the artifacts such as web sites visited, malicious URLs, time stamps, counts of access, search histories, cookies, downloaded activities etc. However, leveraging and locating this information can be challenging without the needed prerequisite information. This paper presents how to perform Forensics analysis of data structures used by popular web browsers such as Chrome, Opera, Mozilla Firefox, and Dolphin on Android and how a Forensic Investigator can acquire Forensic artifacts from web browsers. To strengthen digital investigation, a toolkit named as AndroKit is proposed for Android web browsers Forensics. The paper demonstrates that the AndroKit can successfully acquire and analyze Forensic evidence such as Web History, Downloads, Cookies, Bookmarks, Chrome stored user credentials, decode base64 encoded images, Tabs information etc. Finally, a comparative analysis of AndroKit with standard Forensic tool-kits such as Oxygen Forensics, Andriller, MOBILedit and Belkasoft evidence center has been presented.
Antje Winkler - One of the best experts on this subject based on the ideXlab platform.
-
efficient estimation and large scale evaluation of lateral chromatic aberration for digital image Forensics
Proceedings of SPIE, 2010Co-Authors: Thomas Gloe, Karsten Borowka, Antje WinklerAbstract:The analysis of lateral chromatic aberration forms another ingredient for a well equipped toolbox of an image Forensic Investigator. Previous work proposed its application to forgery detection 1 and image source identification. 2 This paper takes a closer look on the current state-of-the-art method to analyse lateral chromatic aberration and presents a new approach to estimate lateral chromatic aberration in a runtime-efficient way. Employing a set of 11 different camera models including 43 devices, the characteristic of lateral chromatic aberration is investigated in a large-scale. The reported results point to general difficulties that have to be considered in real world investigations.
-
efficient estimation and large scale evaluation of lateral chromatic aberration for digital image Forensics
Proceedings of SPIE, 2010Co-Authors: Thomas Gloe, Karsten Borowka, Antje WinklerAbstract:The analysis of lateral chromatic aberration forms another ingredient for a well equipped toolbox of an image Forensic Investigator. Previous work proposed its application to forgery detection 1 and image source identification. 2 This paper takes a closer look on the current state-of-the-art method to analyse lateral chromatic aberration and presents a new approach to estimate lateral chromatic aberration in a runtime-efficient way. Employing a set of 11 different camera models including 43 devices, the characteristic of lateral chromatic aberration is investigated in a large-scale. The reported results point to general difficulties that have to be considered in real world investigations.
Charles L. Brooks - One of the best experts on this subject based on the ideXlab platform.
-
CHFI Computer Hacking Forensic Investigator Certification All-in-One Exam Guide
McGraw-Hill Education, 2016Co-Authors: Charles L. BrooksAbstract:An all-new exam guide for version 8 of the Computer Hacking Forensic Investigator (CHFI) exam from EC-Council Get complete coverage of all the material included on version 8 of the EC-Council\u27s Computer Hacking Forensic Investigator exam from this comprehensive resource. Written by an expert information security professional and educator, this authoritative guide addresses the tools and techniques required to successfully conduct a computer Forensic investigation. You\u27ll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass this challenging exam, this definitive volume also serves as an essential on-the-job reference. CHFI Computer Hacking Forensic Investigator Certification All-in-One Exam Guide covers all exam topics, including: • Computer Forensics investigation process • Setting up a computer Forensics lab • First responder procedures • Search and seizure laws • Collecting and transporting digital evidence • Understanding hard disks and file systems • Recovering deleted files and partitions • Windows Forensics • Forensics investigations using the AccessData Forensic Toolkit (FTK) and Guidance Software\u27s EnCase Forensic • Network, wireless, and mobile Forensics • Investigating web attacks • Preparing investigative reports • Becoming an expert witnes
-
CHFI Computer Hacking Forensic Investigator Certification All-in-One Exam Guide
2014Co-Authors: Charles L. BrooksAbstract:An all-new exam guide for version 8 of the Computer Hacking Forensic Investigator (CHFI) exam from EC-Council Get complete coverage of all the material included on version 8 of the EC-Council's Computer Hacking Forensic Investigator exam from this comprehensive resource. Written by an expert information security professional and educator, this authoritative guide addresses the tools and techniques required to successfully conduct a computer Forensic investigation. You'll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass this challenging exam, this definitive volume also serves as an essential on-the-job reference. CHFI Computer Hacking Forensic Investigator Certification All-in-One Exam Guide covers all exam topics, including: Computer Forensics investigation process Setting up a computer Forensics lab First responder procedures Search and seizure laws Collecting and transporting digital evidence Understanding hard disks and file systems Recovering deleted files and partitions Windows Forensics Forensics investigations using the AccessData Forensic Toolkit (FTK) and Guidance Software's EnCase Forensic Network, wireless, and mobile Forensics Investigating web attacks Preparing investigative reports Becoming an expert witness Electronic content includes: 300 practice exam questions Test engine that provides full-length practice exams and customized quizzes by chapter or by exam domain PDF copy of the book